
– Alessio Panni
Partner, Head of Cloud & Platforms, Prometeia
– Alessio Panni
Partner, Head of Cloud & Platforms, Prometeia
Introduction
For Prometeia, an advisory and software solutions company that has sat at the frontier of the financial market for over half a century, cloud is a core SaaS enabler. In today’s rapidly evolving landscape, though, the cloud brings both rain and shine. Integrating cloud technology creates new opportunities while opening new attack surfaces and an entire encyclopedia of risks, and the risks and opportunities that come with AI technology are much the same.
With trust being a north star at Prometeia, it became increasingly important to secure IT infrastructure, including cloud assets, and to improve operational resilience by sharpening the overall focus on risk management and making compliance with top-tier security programs the default state.
What Prometeia needed to get there was a context-conscious GRC automation platform that could manage security risks efficiently and transparently by integrating IT, security operations, and regulatory compliances at every organizational level, backed by the ability to confidently demonstrate security and compliance posture.
“Transparency is a guiding value at Prometeia. This means accountability internally and open communication with clients and partners. We wanted to redesign our compliance practice around this, to build trust throughout the organization and the market at large,” says Alessio Panni, Partner, Head of Cloud & Platforms at Prometeia.
The Problem
Securing the business meant embedding Prometeia’s key digital drivers, IT infrastructure, security operations, and regulatory compliance, deeply into the organization’s operations so it could stay on top of any deviations, systemic risks and compliance risks in particular, and respond better and faster.
In practice, this involved designing an “always-on” security program in which proactive risk management and compliance monitoring stood as essential pillars of the cloud and AI strategy. Having compared traditional approaches to GRC management with automated platforms, and given the multiple layers of technological orchestration required to achieve compliance, Prometeia had little doubt about adopting a platform-based approach to achieving its goals.
Alessio was tasked with taking the lead on designing Prometeia’s new cohesive trust program, primarily for its SaaS business journey. Joining forces with the heads of security compliance and IT risk, he began exploring GRC platforms that could embed the pillars of trust and transparency into operations across Prometeia. Through the evaluation phase, Alessio was also keenly aware of the need to ‘demonstrate’ trust.
“The market needs a third party to vouch for you, and certification is a good way to go about this,” he remarks.
Prometeia’s previous approach to compliance was admittedly traditional. The company was already ISO 27001 certified and had built up a strong internal IT function, yet still relied on consultants for certification renewals. The biggest challenge, however, was visibility, as Prometeia needed to ensure clear accountability in security operations while maintaining a near real-time picture of what was happening.
“We need stability, automation, and efficiency in our internal processes especially in the run phase, without impacting agility, innovation, and the time to market of our SaaS offer,” Alessio says. This proved to be a struggle especially during recertification, which made an automated approach attractive to Alessio and the Prometeia team.
Automation was one criterion among several on the hunt for the right compliance automation platform. Context-consciousness mattered because Prometeia wanted to manage GRC programs, regulatory compliance in particular, within its unique context, with the requisite integrations to ensure total cloud asset coverage. Scalability was a must-have, in the form of a unified scheme to support and manage multiple regulatory frameworks in parallel.
“Continuous monitoring helps from day one. It connects all the pieces and helps delegate tasks to specific roles and accounts without losing track or control. When it comes to applying compliance principles, automation is a gamechanger,” says Alessio.
Flexibility was equally important, since Prometeia was not originally digital-first and needed a seamless way to transition and transform capabilities as per new business needs. Demonstrability, through a Trust Center and similar capabilities that provably show the state of risks, compliance, and security posture, was crucial given the company’s industry segment.
Efficiency became the need of the hour, with filling out security questionnaires and balancing costs a pressing challenge. And because transparency is a guiding value at Prometeia, the company expected openness from its GRC vendor too, explicitly looking for a platform that provided the implementation support and direction required for a seamless transition.
The Solution
Having evaluated 5-6 GRC platforms along these criteria, Prometeia selected Sprinto after running a guided pilot to build comfort and establish value. “Agility and flexibility were key elements we carefully looked at during the selection of the technology partner, and then tested during the pilot phase. We are very happy to have found them in Sprinto,” says Alessio.
On Sprinto, Prometeia centrally monitors and manages its security programs, drawing in-depth, real-time insights into risk, control performance, and overall compliance posture, with capabilities that minimize the effort required to scale compliance and help demonstrate posture with clarity and confidence.
Prometeia’s goal for 2023 was to future-proof the business. That meant staying relevant to the market by building the capabilities to demonstrate trust and getting compliances in shape by the end of 2024. With the ISO 27001 certification audit approaching 6-7 months from starting with Sprinto, Alessio was keen on leveraging the platform’s automation to prepare for and run both the ISO and SOC 2 audits, with DORA next in line depending on how those went.
Reducing audit preparation time and maintaining operational velocity consequently became key metrics for the engagement.
Prometeia took two months to integrate Sprinto fully into its unique cloud environment. Those two months also covered uploading and organizing policies, integrating IDP (Identity Provisioning) and setting up built-in MDM (Mobile Device Management), linking controls to relevant risk thresholds for assets, transferring control and evidence histories to Sprinto, building a clear roadmap of control gaps, and doing the work to close those gaps.
Sprinto’s responsive native integrations were pivotal in bringing near real-time visibility into Prometeia’s security assets, painting a vivid picture of the security infrastructure and helping Prometeia better manage critical systems. That transparency quickly brought pressing compliance issues to the fore so they could be addressed instantly.
Impact
With centralized, automated compliance driving improved accountability, visibility, and efficiency, Prometeia now has 10+ frameworks activated and managed, including ISO 27001, SOC 2, ISO 27017, ISO 27018, and ISO 27701, along with 4+ audits managed simultaneously and a 90% reduction in compliance efforts.
“Continuous compliance monitoring and reporting has helped build and strengthen relationships at Prometeia. The platform is a source of truth for compliance and makes the subjective more objective. This way people know when something’s amiss and what to do. The sheer number of checks Sprinto runs helps us trust the platform, and the visibility it provides builds transparency. When people are on the same level about compliance, they can have more meaningful conversations. Sprinto has massively improved our inter-team communications, and teams can function with greater independence thanks to confidence in the platform and what it tells us,” says Alessio Panni, Partner, Head of Cloud & Platforms at Prometeia.
Prometeia demonstrates that posture publicly through its Trust Center, answering the market on risks, compliance, and security without slowing agility, innovation, or the time to market of its SaaS offer.
Got questions? Talk to our experts!



Financial services advisory and software
Italy




